equalizedigital / accessibility-checker

GNU General Public License v2.0
14 stars 8 forks source link

Subscriber restrictions needed in the WP admin #531

Closed amberhinds closed 6 months ago

amberhinds commented 6 months ago

Please give us a description of what happened.

I'm logged in as a subscriber, and I can see the accessibility status of the website:

Screenshot 2024-03-12 at 10 40 31 PM

Only the main page is visible, not sub-pages, but this should not be visible at all.

Also the dashboard widget should not be visible

Screenshot 2024-03-12 at 10 42 22 PM

How can we reproduce this behavior?

Log in as a subscribe on one of our testing sites

Technical info

amberhinds commented 6 months ago

I'm calling this critical because it could leak really sensitive information about websites.

pattonwebz commented 6 months ago

This was resolved with #533 and released in v1.9.3